Data Processing Agreement (DPA)
Processing agreement within the meaning of Article 28 of the GDPR — applicable to the GSE-Web service.
Last updated: 06/30/2026
This translation is provided for information only. The French version is the only legally binding text in case of dispute.
Purpose of this document: it governs the processing, by KLS-Concept (the "Processor"), of the personal data entrusted by the Customer (the "Controller") in connection with the use of the GSE-Web service. It forms an annex to the General Terms of Use and Sale. A signed version, naming the Customer, is available on request at contact@kls-concept.com.
1. Parties
The Processor: Frédéric KULAS, Sole Trader operating under the trade name KLS-Concept, registered with the Alençon Trade and Companies Register under SIREN number 817 714 660, whose place of business is located at 4 chemin du binai, 61300 Crulai (France). Contact: contact@kls-concept.com.
The Controller: the professional Customer subscribing to the GSE-Web service, identified upon subscription (company name, SIREN/SIRET, address). The Customer determines the purposes and means of processing the data it hosts in GSE-Web.
2. Subject matter and duration
The purpose of this agreement is to define the conditions under which the Processor processes, on behalf of and on the instructions of the Controller, the personal data necessary for the provision of the GSE-Web service (stock management, logistics and associated modules).
It applies for the entire duration of the subscription to the service and terminates with it, subject to the obligations to return and delete data described in Article 9.
3. Description of the processing
The essential characteristics of the processing are as follows:
Nature and purpose: hosting, storage, organization and provision of the data entered by the Customer in GSE-Web, for the purposes of managing its stock, its logistics operations, its users and, where applicable, its own customers (OMS portal) and learners (Education module).
Categories of data subjects: the Customer's users (employees, authorized staff), and where applicable its customers (OMS third parties), its contacts and, for the Education module, teachers and learners.
Categories of data: identification and contact data (last name, first name, e-mail, login identifier, role/permissions), activity and logging data (logins, stock movements, actions performed), as well as the business data entered by the Customer. No special category of sensitive data is required by the service; the Customer undertakes not to introduce any without an appropriate legal basis.
Retention period: the data is retained for the entire duration of use of the service. In the event of non-renewal, it remains restorable for 30 days, then is kept in backup for 3 months before permanent deletion (see Article 9).
4. Obligations of the Processor (Article 28.3 of the GDPR)
The Processor undertakes to:
a) Process on instructions — process the data only on the documented instructions of the Controller, including with regard to transfers, unless required to do so by law; in such a case, it shall inform the Controller before processing, unless prohibited by law.
b) Confidentiality — ensure that persons authorized to process the data (including its own technical service providers) have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
c) Security — implement the appropriate technical and organizational measures within the meaning of Article 32 of the GDPR (see Article 6).
d) Sub-processing — engage another processor only with the authorization of the Controller, the latter acknowledging and accepting the list set out in Article 5; the Processor informs the Controller of any change and imposes the same protection obligations on the new processor.
e) Rights of data subjects — assist the Controller, by appropriate technical and organizational measures, in responding to requests to exercise the rights of data subjects (access, rectification, erasure, restriction, portability, objection). The data export function and the account deletion feature built into GSE-Web contribute to this assistance.
f) Security and compliance assistance — assist the Controller in complying with its obligations regarding security, breach notification, data protection impact assessments (DPIA) and prior consultation, taking into account the information available to the Processor.
g) Fate of the data — at the Controller's choice, delete or return the data at the end of the service, and destroy existing copies, unless required by law to retain it (see Article 9).
h) Documentation and audit — make available to the Controller the information necessary to demonstrate compliance with its obligations and allow audits to be carried out, under the conditions of Article 8.
5. Authorized sub-processors
The Controller authorizes the Processor to use the following sub-processors, each for the indicated purpose:
- •Amazon Web Services (AWS) — hosting of the database and application backend, eu-central-1 region (Frankfurt, Germany, EU).
- •PlanetHoster — hosting of the PWA application and technical logs (France); backups performed in Switzerland (a country benefiting from an adequacy decision under Article 45 of the GDPR).
- •Stripe — processing of card payments.
- •Tiime — invoicing and accounting.
- •Acumbamail — sending of transactional and informational e-mails.
- •TidyCal (appointment scheduling) and Vbout (management of prospect contacts). In addition, an independent technical service provider acts as a sub-processor for the maintenance of the application backend.
The Processor will inform the Controller of any addition or replacement of a sub-processor, giving the latter the opportunity to raise legitimate objections.
6. Data location and transfers
The data is hosted within the European Union (France and Germany). Backups are performed in Switzerland, a country recognized as ensuring an adequate level of protection by the European Commission (Article 45 of the GDPR). No transfer is carried out to a third country that does not provide appropriate safeguards within the meaning of Chapter V of the GDPR.
7. Security measures (Article 32)
The Processor implements appropriate technical and organizational measures, including:
- •encryption of communications (HTTPS/TLS) between users and the service;
- •access control: authentication, management of permissions per user, access to data restricted to authorized persons only;
- •logging of connections and actions, for limited durations (7 days locally, 30 days in development, 90 days for critical errors only) followed by anonymization;
- •regular (daily) backups allowing data restoration;
- •segregation of environments and protective measures against unauthorized access.
8. Data breach and audit
In the event of a personal data breach, the Processor notifies the Controller as soon as possible after becoming aware of it, and provides it with the relevant information to enable it, where applicable, to notify the CNIL within the 72-hour deadline and to inform the data subjects concerned.
The Processor makes available to the Controller the documentation necessary to demonstrate compliance and submits to reasonable audits (on notice and in compliance with confidentiality and continuity of service), carried out by the Controller or a third party mandated by it.
9. Fate of the data at the end of the service
The Customer may, at any time and before the end of the service, export its business data (products, stock, stock movements) from its administrator account. Photographs and image files cannot be returned by this function: it is the Customer's responsibility to back them up.
In the event of non-renewal or termination, the data remains restorable for 30 days, then is kept in backup for 3 months before permanent deletion. Upon the Customer's express request, early deletion may be carried out, subject to legal retention obligations (in particular invoices, retained for 10 years).
10. Liability and applicable law
Each party is liable for damage caused by failure to comply with its obligations under the GDPR. The Controller warrants that the data it introduces into the service is lawful and that it has the legal bases necessary for its processing.
This agreement is governed by French law. Any dispute falls under the jurisdiction of the Commercial Court of Alençon. It supplements the General Terms of Use and Sale, of which it forms an annex; in the event of a conflict regarding data protection, this agreement prevails.